VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure

2026-05-14 Hybrid Analysis

https://hybrid-analysis.blogspot.com/2026/05/velvet-chollima-infostealer-campaign.html

Thumbnail for VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure

Hybrid Analysis identified a VELVET CHOLLIMA-assessed infostealer operation distributing a signed Windows MSI that masquerades as the Tralert FX cryptocurrency trading application. The installer exposed live credentials and GitLab access tokens, revealing a multi-stage loader chain that uses GitLab repositories for payload delivery, scheduled-task persistence, and recurring exfiltration. The malware collects host reconnaissance, keylogs, and Chromium browser credentials, then pushes stolen data into GitLab repositories every 30 minutes for human triage of cryptocurrency-focused victims. The final payload is MoonPeak, a custom XenoRAT variant, with infrastructure including Tralert/Talert lure domains, GitLab projects, C2 hosts, mutexes, hashes, and the hardcoded C2 IP 91.107.246.107. The campaign matters because the exposed repositories showed active compromise, more than 4,100 commits, roughly 90 affected hosts, and an operational focus on crypto account takeover.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2026-05-14 2026-05-14
EMAIL [email protected] 2026-05-14 2026-05-14
EMAIL [email protected] 2026-05-14 2026-05-14
EMAIL [email protected] 2026-05-14 2026-05-14
URL https://github.com/Fujinuma0804… 2026-05-14 2026-05-14
URL https://github.com/vergiegpham/… 2026-05-14 2026-05-14
URL http://161.97.113.34:3001/api/t… 2026-05-14 2026-05-14
DOMAIN endava.online 2026-05-14 2026-05-14
DOMAIN talert.space 2026-05-14 2026-05-14
DOMAIN talert.online 2026-05-14 2026-05-14
DOMAIN talert.store 2026-05-14 2026-05-14
DOMAIN talert.site 2026-05-14 2026-05-14
DOMAIN tralert.store 2026-05-14 2026-05-14
DOMAIN tralert.site 2026-05-14 2026-05-14
DOMAIN trumpalert.store 2026-05-14 2026-05-14
DOMAIN tralert7.com 2026-05-14 2026-05-14
DOMAIN tralert.online 2026-05-14 2026-05-14
IPv4 91.107.246.107 2026-05-14 2026-05-14
IPv4 161.97.113.34 2026-05-14 2026-05-14
HASH 8bcfedccf028a08dafd34a01b036799f 2026-05-14 2026-05-14
HASH 4794c3cca9a860c8500f51d430cf2392 2026-05-14 2026-05-14
HASH 666da559f02a9b217a4c826b17923c0c 2026-05-14 2026-05-14
HASH f10d35fedb6aa986cef4c113edfdef26 2026-05-14 2026-05-14

Related Actors

Related Reports

2026-04-17 • 33% Match
#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
Shares tags: Phishing, T1056.001, T1053.005 • Published within a month
« Back